Start from a trusted device and official address
Open the platform’s app or type its known address yourself. Do not begin from a direct message, sponsored result, or unexpected “security” email. If the platform suggests using a familiar device or browser, do that: Facebook, for example, directs people to its hacked-account flow from a device previously used to sign in.[2]
Secure the email account and phone number used for recovery
If someone controls your recovery email or mobile account, they may be able to reset the social account again. Check that you still receive messages, remove unfamiliar forwarding or recovery settings, and follow our separate email security checklist. This article focuses on the social account after a takeover; it does not replace recovery for a compromised mailbox or mobile number.
Use the platform’s hacked-account recovery flow
Follow the provider’s current prompts. Expect to confirm an email address or phone number, reverse an unauthorized change, or provide another form of verification. Instagram says available recovery steps can differ by account and recommends trying the options shown in its official recovery flow.[3] Never pay a stranger who claims they can recover the account.
Replace the password and remove other sessions
Create a password that is unique to this account. Then review signed-in devices, locations, and sessions; remove anything you do not recognize. If the old password was reused elsewhere, replace it on those accounts too. Google’s compromised-account guidance similarly tells users to change reused passwords and remove unfamiliar signed-in devices.[4]
Repair recovery details, MFA, and linked access
Confirm the recovery email, phone number, username, and account name. Remove unknown authenticator methods, trusted devices, passkeys, backup codes, connected apps, business managers, and delegated roles. Generate new backup codes if old ones may have been seen. Turn on MFA after the account details are yours again; CISA explains that MFA adds another verification step, so a stolen password alone is not enough to access the account.[5]
Inspect posts, messages, ads, and payment activity
Look for posts, stories, comments, messages, follows, profile links, ad campaigns, marketplace listings, or purchases you did not make. Save screenshots and dates before deleting material if you may need to report fraud, threats, or impersonation. Remove unauthorized content and check any payment method or advertising account linked to the profile.
Warn contacts without spreading the scam
Tell followers or frequent contacts that the account was compromised, especially if it sent links, requests for money, investment pitches, or urgent favors. Describe the message rather than reposting a malicious link. Ask recipients not to reply, click, pay, or share codes.
Watch for a second takeover attempt
Recheck sessions, recovery details, linked apps, and outbound messages after the first cleanup. Keep confirmation emails and recovery case numbers. If you see identity theft, payment fraud, or misuse of personal information, use the relevant official reporting and recovery channel rather than relying only on the social platform.
Platform screens and recovery options change. Use the provider’s current official instructions. Digital Safety Desk is not affiliated with any listed platform, and no recovery method can guarantee restoration of an account.
